# How to search in Elasticsearch when same field is present multiple times?

**URL:** <https://discuss.elastic.co/t/how-to-search-in-elasticsearch-when-same-field-is-present-multiple-times/305385>\
**Category:** Elasticsearch\
**Tags:** eql-elastic-query-language\
**Created:** [May 23, 2022, 9:50am UTC](https://discuss.elastic.co/t/how-to-search-in-elasticsearch-when-same-field-is-present-multiple-times/305385 "2022-05-23T09:50:50Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![Vipul\_Kumar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vipul_kumar/32/105771_2.png) [@Vipul\_Kumar](https://discuss.elastic.co/u/Vipul_Kumar)\
**Post date:** [May 23, 2022, 9:50am UTC](https://discuss.elastic.co/t/how-to-search-in-elasticsearch-when-same-field-is-present-multiple-times/305385/1 "2022-05-23T09:50:50Z")

</div>

I'm trying to figure out how do I search an index when same field is present multiple times. Look at the below example:

```auto
"_source" : {
          "field1" : "value1",
          "field_list" : [
            {
              "xx" : "aa",
              "yy" : "bb",
              "zz" : "cc"
            },
            {
              "xx" : "acfg",
              "yy" : "abcd123",
              "zz" : "xyz321"
            }
			],
          "tags" : [
            "_aggregatefinalflush"
          ],
          "field3" : null
        }

```

I want to query with "xx" and "yy" as parameter. But when I search like this:

```auto
GET /indexname/_search
{
  "query": {
    "bool": {
      "must": [
        {
          "match": {
            "field_list.xx": "aa"
          }
        },
        {
          "match": {
            "field_list.yy": "abcd123"
          }
        }
      ]
    }
  }
}

```

It returns this document. I want to get this document only when "xx" and "yy" of the same object matches with the parameter. Is it possible? If yes, could anyone please share the correct way to query? Thanks in advance!

---

<div class="post-metadata">

**Author:** ![RabBit\_BR](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rabbit_br/32/82261_2.png) [@RabBit\_BR](https://discuss.elastic.co/u/RabBit_BR)\
**Post date:** [May 23, 2022, 12:41pm UTC](https://discuss.elastic.co/t/how-to-search-in-elasticsearch-when-same-field-is-present-multiple-times/305385/2 "2022-05-23T12:41:07Z")

</div>

Hi!  
What type is "field\_list" field?

---

<div class="post-metadata">

**Author:** ![Vipul\_Kumar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vipul_kumar/32/105771_2.png) [@Vipul\_Kumar](https://discuss.elastic.co/u/Vipul_Kumar)\
**Post date:** [May 23, 2022, 4:11pm UTC](https://discuss.elastic.co/t/how-to-search-in-elasticsearch-when-same-field-is-present-multiple-times/305385/3 "2022-05-23T16:11:15Z")

</div>

Hey!

My mapping looks something like this:

```auto
"mappings" : {
      "properties" : {
        "field_list" : {
          "properties" : {
            "xx" : {
              "type" : "text",
              "fields" : {
                "keyword" : {
                  "type" : "keyword",
                  "ignore_above" : 256
                }
              }
            },
            "yy" : {
              "type" : "date"
            },
            "zz" : {
              "type" : "text",
              "fields" : {
                "keyword" : {
                  "type" : "keyword",
                  "ignore_above" : 256
                }
              }
            }
          }
        },
        "field1" : {
          "type" : "text",
          "fields" : {
            "keyword" : {
              "type" : "keyword",
              "ignore_above" : 256
            }
          }
        }
	}
}

```

Just FYI, this nested field is constructed through logstash 'aggregate' filter plugin while inserting the json fetched from DB.

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [May 23, 2022, 4:20pm UTC](https://discuss.elastic.co/t/how-to-search-in-elasticsearch-when-same-field-is-present-multiple-times/305385/4 "2022-05-23T16:20:10Z")

</div>

For your query to work you need to change your mapping to use [nested field type](https://www.elastic.co/guide/en/elasticsearch/reference/8.2/nested.html) and then rewrite you query as a [nested query](https://www.elastic.co/guide/en/elasticsearch/reference/8.2/query-dsl-nested-query.html).

---

<div class="post-metadata">

**Author:** ![RabBit\_BR](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rabbit_br/32/82261_2.png) [@RabBit\_BR](https://discuss.elastic.co/u/RabBit_BR)\
**Post date:** [May 23, 2022, 5:03pm UTC](https://discuss.elastic.co/t/how-to-search-in-elasticsearch-when-same-field-is-present-multiple-times/305385/5 "2022-05-23T17:03:40Z")

</div>

I would take Christian advice.

---

<div class="post-metadata">

**Author:** ![Vipul\_Kumar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vipul_kumar/32/105771_2.png) [@Vipul\_Kumar](https://discuss.elastic.co/u/Vipul_Kumar)\
**Post date:** [May 24, 2022, 4:34am UTC](https://discuss.elastic.co/t/how-to-search-in-elasticsearch-when-same-field-is-present-multiple-times/305385/6 "2022-05-24T04:34:35Z")

</div>

Thank you so much for the reply @Christian_Dahlqvist.

So, basically I need to define mapping from the logstash while indexing. Could you please share any documentation where I could define mapping from logstash?

Also, most of the mapping created by logstash is ok, and only one mapping (field\_list) I need to define in logstash. So, can I define only single mapping?

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [May 24, 2022, 4:42am UTC](https://discuss.elastic.co/t/how-to-search-in-elasticsearch-when-same-field-is-present-multiple-times/305385/7 "2022-05-24T04:42:08Z")

</div>

You generally specify mappings through [index templates](https://www.elastic.co/guide/en/elasticsearch/reference/8.1/index-templates.html). You may get Logstash to upload this for you but I prefer to manage it directly in Elasticsearch instead.

---

<div class="post-metadata">

**Author:** ![Vipul\_Kumar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vipul_kumar/32/105771_2.png) [@Vipul\_Kumar](https://discuss.elastic.co/u/Vipul_Kumar)\
**Post date:** [May 24, 2022, 6:30am UTC](https://discuss.elastic.co/t/how-to-search-in-elasticsearch-when-same-field-is-present-multiple-times/305385/8 "2022-05-24T06:30:41Z")

</div>

Thank you so much! I think index template is what I was looking for.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 21, 2022, 6:30am UTC](https://discuss.elastic.co/t/how-to-search-in-elasticsearch-when-same-field-is-present-multiple-times/305385/9 "2022-06-21T06:30:44Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
